Affected by GO-2025-3615
and 10 other vulnerabilities
GO-2025-3615 : Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
GO-2026-4381 : Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
GO-2026-4382 : Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
GO-2026-5268 : Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
GO-2026-5337 : Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
GO-2026-5351 : Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
GO-2026-5371 : Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
GO-2026-5374 : Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
GO-2026-5575 : kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
GO-2026-5594 : Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
GO-2026-5621 : Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access in github.com/kyverno/kyverno
Discover Packages
github.com/kyverno/kyverno
pkg
utils
git
package
Version:
v1.16.0
Opens a new window with list of versions in this module.
Published: Nov 7, 2025
License: Apache-2.0
Opens a new window with license information.
Imports: 9
Opens a new window with list of imports.
Imported by: 1
Opens a new window with list of known importers.
Documentation
Documentation
¶
Source Files
¶
Click to show internal directories.
Click to hide internal directories.